[curves] Million Dollar Curve

Thomas Ptacek thomas at sockpuppet.org
Wed Feb 24 10:28:32 PST 2016

1. CryptoExperts is like a European version of Cryptography Research; it’s people from Gemalto, INRIA, Antoine Joux, Lous Goubin, their grad students, &c. They’re not randos.

2. Their paper doesn’t claim anything is wrong with 25519. They’re just proposing a random Edwards curve alternative to 25519, with a cute trick to generate credible random parameters. Their paper rejects the Brainpool-y parameters-from-math-constants approach, citing Bernstein’s BADA55 argument, in favor of pure random parameters. 

Thomas Ptacek

On February 24, 2016 at 12:20:05 PM, Salz, Rich (rsalz at akamai.com) wrote:

> > http://cryptoexperts.github.io/million-dollar-curve/  

Who are these folks? What is wrong with25519 and/or 448?  

My answers: I don't know and nothing.  

So why do I want this?  

Curves mailing list  
Curves at moderncrypto.org  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/curves/attachments/20160224/0133384e/attachment.html>

More information about the Curves mailing list